Executive brief
connectrpc is a gRPC framework for Rust that handles client requests. When streaming calls finish early, the library continues reading the client's request body indefinitely without timing out. An attacker can exploit this by sending partial or stalled requests to exhaust a server's memory, file descriptors, and task resources, potentially causing denial of service.
Technical details
The vulnerability exists in background task handling for client-streaming and bidirectional-streaming calls; these tasks begin reading request bodies before interceptors or handlers run and continue indefinitely even after the handler completes or times out, with no timeout on the reader itself. An unauthenticated network attacker can open multiple stalled streams on a single connection to exhaust resources; servers using Tower middleware authentication are only exposed to callers with valid credentials. Versions 0.2.0–0.7.0 and 0.9.0 are affected; patches in 0.8.2 and 0.9.1 apply a 5-second timeout and 1 MiB discard limit after the handler exits.
Affected products
- connectrpc connectrpc 0.2.0 to 0.7.0, 0.9.0
Timeline
- 2026-09-21: disclosed
- 2026-09-23: advisory
- 2026-09-23: patched: Versions 0.8.2 and 0.9.1